CVE-2026-82078
PaperCut MF/NG unsafe dynamic class loading may allow arbitrary code execution (CVE-2026-82078)
PaperCut MF/NG has an unsafe dynamic class loading flaw in database connection utilities. High-privileged attackers who can alter configuration may run arbitrary Java bytecode. CISA KEV and SSVC report active exploitation; fixed releases are available. Upgrade promptly.
What happened
PaperCut MF/NG contains an unsafe dynamic class loading weakness in its database connection utilities. The application instantiates database driver classes from configurable driver names without checking them against an allowlist. If an attacker can manipulate system configuration parameters, they can execute arbitrary Java bytecode already present on the application classpath under the security context of the PaperCut server process.
The CVSS 4.0 vector rates this 9.4 (critical), with a network attack vector, low attack complexity and no user interaction, but high privileges required. CISA KEV added CVE-2026-82078 on 31 August 2026, and CISA SSVC reports active exploitation; CISA KEV also lists it. The CVE record does not note public exploit disclosure.
Who is affected
Affected releases are PaperCut MF/NG before 24.1.10, 25.0.0 to before 25.0.13, and 26.0.0 to before 26.0.5. This includes older installations, the 25.0.0 to before 25.0.13 range, and the 26.0.0 to before 26.0.5 range. The flaw sits in database connection utilities, so any affected PaperCut server should be treated as in scope, with particular attention to hosts reachable over the network or where system configuration changes are possible.
What to do now
- Confirm whether you are running an affected release: before 24.1.10, 25.0.0 to before 25.0.13, or 26.0.0 to before 26.0.5.
- Upgrade to the matching fixed release: PaperCut MF/NG 24.1.10, PaperCut MF/NG 25.0.13, or PaperCut MF/NG 26.0.5. The CVE record states a fix is available in these releases.
- If you cannot upgrade immediately, restrict network access to the PaperCut server to trusted administrators and review system configuration changes. CISA KEV lists 14 September 2026 as the due date for required action.
- CISA KEV's required action also directs applying mitigations in accordance with vendor instructions, ensuring compliance with CISA BOD 26-04 and CISA's Forensics Triage Requirements, and following applicable BOD 26-04 guidance for cloud services or discontinuing use of the product if mitigations are unavailable. No separate vendor-specific workaround is included in the CVE record.
How to detect it
The CVE record and CISA KEV entry do not provide vendor-supplied indicators of compromise or log signatures. Because CISA KEV and CISA SSVC report active exploitation, treat an affected server that cannot be patched immediately as higher risk. Review database configuration for unexpected or unapproved driver class names, and restrict and monitor network access to the server until a fixed version is applied.
Beyond the patch
Because CISA KEV and CISA SSVC report active exploitation, detection and response should not wait for the next patch cycle; Managed Detection & Response (MDR) can monitor for post-exploitation behaviour on affected servers. PaperCut MF/NG is third-party software whose patching cadence sets your exposure window, so Supply Chain Defense & Third-Party Risk can help keep products like this in inventory so a KEV entry is not the first warning you get.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| PaperCut MF/NG | – < 24.1.10 25.0.0 – < 25.0.13 26.0.0 – < 26.0.5 | 24.1.10 25.0.13 26.0.5 |